Direct answer
Treat a suspension or restriction as a visible state, not a confirmed cause. In the first-hour phase, freeze unsafe changes, capture the exact notice and scope, classify enforcement versus payment, verification, security, outage, or linked-container cascade, and preserve independent evidence. Use the current first-party route for the account and region, reconcile billing and measurement as separate ledgers, and call the account recovered only after access, ownership, persistence, dependencies, finance, and a monitored test pass. Provider review and recovery remain provider-dependent. Synthesis/inference from incident-response, evidence-preservation, monitoring, and platform-state sources. [RS-S03][RS-S09][DRS-A01][PR-P10][PR-P13]
Who this is for
Fit: operators, finance owners, security leads, agencies, and executives responsible for high-spend Meta, Google Ads, TikTok, or multi-platform programs when an account is suspended, restricted, read-only, unable to deliver, or under a payment/verification hold. It also fits a near miss involving an unauthorized change or linked-container event.
Non-fit: anyone seeking a shortcut around enforcement, a replacement account, identity/payment rotation, forged documents, cloaking, credential sharing, or guaranteed reinstatement. This is not a substitute for current platform instructions, legal counsel, an insurer/broker, bank-fraud handling, or digital forensics. Synthesis/inference: each outside party retains its own decision authority. [PR-P07][DRS-A03]
Decision model
| Label | Meaning | Treatment |
|---|---|---|
| Controlled | Export, access review, freeze, approval, or other advertiser-owned action. | Name owner, evidence location, and read-back. |
| Observed | Notice, status page, dashboard, bank record, or customer symptom. | Preserve and corroborate; do not call it the cause. |
| Provider-dependent | Platform, issuer, bank, or other outside party decides or executes it. | Use the official route; make no timing or outcome promise. |
| Unknown | Scope, ownership, evidence, or relationship is unverified. | Record the gap and stop blast-radius-expanding changes. |
A suspension label can coexist with a payment lock, verification request, compromised session, parent-container action, outage, or measurement failure. Synthesis/inference: classify the visible state first and keep competing hypotheses open. Provider and user signals can disagree; a green status page is not proof that an account-specific problem is absent. [RS-S19][PR-P01][PR-P09]
Diagnostic or control sequence
This is a first-hour-to-recovery operating path, not a provider timetable. Every step names evidence/input, owner, action, and stop/branch condition.
- Open the incident record. Input: exact label/raw error, platform surface, account/portfolio/manager/campaign IDs, region, legal entity, UTC first-seen time, last-known-good export, and business symptom. Owner: incident lead plus recorder. Action: write the symptom without a cause statement; preserve notice URL, request ID, and case ID. Stop if the message came from an inbound “support” contact; use the platform domain directly. [DRS-A01][RS-S03][DRS-A15]
- Assign decision rights. Input: owner/admin map, partner or manager links, billing owner, security and finance contacts, and restart approver. Owner: asset owner. Action: name one incident lead, executor, recorder/communications owner, finance owner, and platform liaison. Stop if no authorized owner is reachable; record unavailable authority and perform only pre-authorized capture. [RS-S09][DRS-A03]
- Classify and map scope. Input: notice detail, policy/billing/verification surface, parent/child links, payment state, recent changes, and delivery snapshot. Owner: incident lead with finance/security as indicated. Action: record enforcement/restriction, payment/transaction risk, verification, takeover, outage/control-plane, reporting/measurement, regional/legal, partner/API, or cascade hypotheses; note an alternative where evidence permits. Stop speculative appeals or edits if the affected object is unclear. Synthesis/inference for this combined taxonomy. [PR-P10][PR-P11][PR-P13][PR-P15]
- Check independent signals. Input: product-scoped status/history, second administrator, UI/API comparison, known-clean device, owned delivery/event/CRM telemetry, bank/card record, and customer symptom. Owner: operations, measurement, and finance owners. Action: timestamp agreement and disagreement. Stop using a suspect endpoint if compromise or malicious extension is plausible. Keep outage, payment, policy, verification, endpoint, and measurement hypotheses open when delivery is zero but access remains. Synthesis/inference. [RS-S07][RS-S19][PR-P01][PR-P09][PR-P21][PR-P24]
- Contain one reversible risk. Input: before-state export, change ledger, sessions/apps/tokens, payment and budget state, and rollback condition. Owner: executor; incident lead approves; security owner leads compromise actions. Action: freeze nonessential edits; pause/reduce activity only within authority when unauthorized spend, exposure, or unsafe automation is plausible; from a known-clean endpoint revoke one identified suspect session/token after preserving logs; record expected/actual read-back. Stop when read-back conflicts, a shared dependency is affected, or blast radius grows. Synthesis/inference from containment and common-mode guidance. [RS-S03][RS-S09][RS-S17][RS-S18][DRS-A01][PR-P12]
- Prepare one factual official escalation. Input: exact label/detail ID, affected IDs, UTC chronology, owner/entity context, authentic corrective actions, exports, and case history. Owner: platform liaison with asset-owner approval. Action: navigate directly to the current first-party route shown for that account and region; separate facts from hypotheses and submit only requested authentic records. Meta, Google, and TikTok routes and labels are mutable. Stop repeated or speculative submissions. [PR-P10][PR-P11][PR-P13][PR-P15]
- Branch billing. Input: platform invoice/balance and transaction ID, served-delivery export, bank/card transaction, authorized-user list, payment profile, and agency invoice/contract. Owner: finance. Action: (a) suspected unauthorized activity—preserve access/transaction evidence and use official platform plus issuer/bank fraud routes; (b) legitimate platform-balance disagreement—reconcile before disputing; (c) agency/reseller mismatch—separate platform charges from management fees and route contract questions to finance/counsel. Stop blanket chargeback advice. Google distinguishes unauthorized activity from reversing a legitimate balance and warns the latter can create suspension risk. Agency branch is synthesis/inference. [BC-S07][BC-S08][BC-S09]
- Quarantine and reconcile measurement. Input: delivery export, event/pixel/CAPI arrival, consent state, analytics, CRM/backend outcome, attribution window, time zone, and freshness/version. Owner: measurement owner with finance/growth. Action: keep billed, served, platform-attributed, analytics/event, and backend-settled records separate; freeze one cohort’s scope and settlement cutoff; record latency, consent, deduplication, and backfill limits. Stop budget conclusions when reports are stale, missing, or cross-tenant; preserve the raw view/export. Synthesis/inference. [RS-S07][RS-S08][PR-P09][PR-P18]
- Run the recovery acceptance gate. Input: provider response/restored state, access diff, dependency map, campaign/automation diff, reconciled ledgers, test event/conversion, and residual-unknown log. Owners: asset owner for access, finance for ledgers, measurement owner for telemetry, incident lead for scope. Action: confirm known-clean endpoint; review password/MFA/recovery contact; remove unauthorized persistence; validate admins, partners, apps, tokens, rules, scripts, payments, domains, catalogs, datasets, and parent/child links; compare current state to the preserved before-state; test destination and event path. Stop if any predicate is unknown or unexpected. Login, dashboard green, case response, or one active campaign is not recovery alone. Synthesis/inference. [DRS-A01][BC-S06][BC-S09]
- Conduct a limited monitored restart. Input: signed gate, authorized budget ceiling, stop condition, independent spend/delivery/event alerts, and monitoring owner. Owner: executor; asset owner approves scope. Action: restart the smallest authorized slice needed to test spend, delivery, event arrival, destination behavior, and reporting; record actual state after each change. Stop on unexpected spend, permissions, endpoint, delivery, or event behavior. Staged restart is synthesis/inference, not a delivery or performance promise. [RS-S07][RS-S08][BC-S06]
- Close with a postmortem and control test. Input: chronology, impact, decision context, successful/failed mitigations, residual finance/measurement gaps, case records, and signatures. Owner: incident lead and recorder. Action: run a blameless review, assign each control change an owner/date, and test the changed export, access, billing, measurement, or restart control in a safe environment/tabletop. Stop closure while material unknowns, missing evidence, or untested corrections remain. Synthesis/inference. [RS-S10][DRS-A03][RS-S09]
Evidence to preserve
Use an access-controlled evidence location, preserve before destructive changes, and log what was unavailable. Synthesis/inference from CISA/NIST preservation guidance. [DRS-A01][RS-S03]
- Exact notice/error/detail reference, URL, and UTC capture time.
- Platform surface, region, legal entity, all affected IDs, and last-known-good/current exports.
- Admin/partner/manager/app/OAuth/token/session/extension/recovery-contact and payment state.
- Recent changes with actor, object, timestamp, expected state, and actual read-back.
- Status/history link, second-admin view, UI/API comparison, clean-device result, and owned telemetry.
- Platform invoice/balance, transaction IDs, bank/card record, authorized-user list, agency invoice, and contract reference.
- Event samples, consent/schema/version, analytics, CRM/backend record, attribution window, and freshness notes.
- Case IDs, submitted chronology, provider requests/replies, collector, access controls, retention decision, and unavailable-evidence log. Minimize personal data. [DRS-A01][RS-S05]
What not to do
- Do not create replacement accounts, rotate identities/payments to evade restrictions, cloak, use anti-detect tools, or forge records. [PR-P07][PR-P10]
- Do not send passwords, MFA codes, cookies, government IDs, full payment data, browser data, scripts, or remote-control access to inbound contacts. Use first-party domains. [DRS-A15]
- Do not spam appeals, make speculative admissions, delete evidence, wipe a suspect device, or rotate a shared dependency before mapping blast radius. [DRS-A01][RS-S17]
- Do not issue an indiscriminate chargeback against a legitimate balance. [BC-S07][BC-S08]
- Do not treat MFA, a successful script run, green dashboard, or restored login as proof every asset is clean or every mutation applied. [BC-S06][RS-S04]
When to escalate
Self-service: one platform/account; clear owner; no suspected unauthorized activity; known dependencies; complete evidence; and a task limited to following current first-party instructions. Keep the incident record and acceptance gate.
Qualified specialist: material spend/customer impact crosses systems or owners; custody, billing entity, or offboarding is unclear; unauthorized access/payment activity is plausible; evidence may matter to bank, counsel, insurer, or law enforcement; a parent container may affect multiple accounts; finance and measurement disagree; or no independent acceptance test exists. Synthesis/inference, not a spend threshold or success prediction. [RS-S09][DRS-A03]
Decline/refer away: evasion, forged evidence, credential surrender, legal/insurance conclusions, unsupported loss valuation, or guaranteed platform outcome. AdsInfra cannot override platform enforcement decisions or promise reinstatement, timing, reimbursement, or performance.
FAQ
What first? Capture the exact label, IDs, UTC time, raw error, notice URL, current billing/verification/policy state, and last-known-good export before editing. Synthesis/inference. [DRS-A01][RS-S03]
Is suspension always policy enforcement? No. Payment/transaction risk, verification, unauthorized activity, parent scope, outage, or measurement failure can coexist with the symptom. The current account notice controls the branch. [PR-P10][PR-P11][PR-P13][PR-P15]
Should we open a new account? Not to bypass a restriction. Preserve the original state and use the official route; related/new accounts may also be affected by enforcement. [PR-P07][PR-P10][PR-P11]
When involve a bank or issuer? When unauthorized activity is suspected, preserve evidence and use official platform and issuer/bank fraud routes. For a legitimate balance disagreement, reconcile first. [BC-S07][BC-S08]
When is it recovered? After owner access, persistence removal, dependency checks, billing/measurement reconciliation, a test event/conversion, limited monitored restart, and signed closure. Login alone is insufficient. Synthesis/inference. [DRS-A01][BC-S06][BC-S09]
Outage or restriction? Keep both hypotheses open, compare status with an authorized second view and owned telemetry, and avoid repeated edits. Use the existing platform-outage-vs-account-specific-problem resource when applicable. Synthesis/inference. [RS-S19][PR-P01][PR-P09][PR-P21]
Source appendix
All sources were accessed 2026-07-19. Before acting, authorized owners should check the current first-party route for the affected account, product surface, and region; labels, eligibility, and timing may vary.
| Key | Title; author/publisher; date | URL | Boundary |
|---|---|---|---|
| RS-S03 | Cybersecurity Incident & Vulnerability Response Playbooks; CISA; 2021 | https://www.cisa.gov/sites/default/files/2024-08/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf | Roles, evidence, containment, recovery; federal thresholds do not transfer. |
| RS-S04 | Multi-Factor Authentication (MFA); CISA; Revision Date January 05, 2022 | https://www.cisa.gov/resources-tools/resources/multi-factor-authentication-mfa | Layered control; not immunity. |
| RS-S05 | Digital Identity Guidelines: Authentication and Authenticator Management (SP 800-63B, 4th ed.); NIST; 2025-08-26 | https://pages.nist.gov/800-63-4/sp800-63b.html | Session/recovery and retention principles; no advertiser assurance-level claim. |
| RS-S07 | Monitoring Distributed Systems; Rob Ewaschuk, Google SRE; 2017 | https://sre.google/sre-book/monitoring-distributed-systems/ | Actionable monitoring; ad metrics are proxies. |
| RS-S08 | Service Level Objectives; Chris Jones et al., Google SRE; 2017 | https://sre.google/sre-book/service-level-objectives/ | Internal objectives; no provider or ROAS SLA. |
| RS-S09 | Managing Incidents; Andrew Stribblehill, Google SRE; 2017 | https://sre.google/sre-book/managing-incidents/ | Command, communication, handoffs; examples adapted. |
| RS-S10 | Postmortem Culture; John Lunney and Sue Lueder; 2017 | https://sre.google/sre-book/postmortem-culture/ | Blameless learning and exercises; no outcome guarantee. |
| RS-S17 | Mapping Disruption Sources in the Power Grid and Implications for Resilience; Maureen S. Golan and Javad Mohammadi; arXiv; 2022-07-17 | https://arxiv.org/abs/2207.08146 | Cross-layer mapping by analogy; not ad statistics. |
| RS-S18 | Comparative Resilience Notions and Vertex Attack Tolerance of Scale-Free Networks; John Matta, Jeffrey Borwey, Gunes Ercal; arXiv; 2014-04-01 | https://arxiv.org/abs/1404.0103 | Bottleneck analogy; no continuity score. |
| RS-S19 | Characterizing User and Provider Reported Cloud Failures; Cetin, Talluri, Iosup; arXiv; 2021-10-23 | https://arxiv.org/abs/2110.12237 | Provider/user visibility can differ. |
| DRS-A01 | Digital Evidence Preservation: Considerations for Evidence Handlers; Barbara Guttman, Douglas R. White, Tracy Walraven; NIST; 2022-09 | https://nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8387.pdf | Preservation, integrity, context, minimization. |
| DRS-A03 | Incident Response Plan Basics; CISA; undated | https://www.cisa.gov/sites/default/files/publications/Incident-Response-Plan-Basics_508c.pdf | Roles/exercises; not private legal advice. |
| DRS-A15 | Tech (non)support: Scammers pose as Meta in Facebook account grab ploy; Sharef Hlal and Karam Chatra; Group-IB; 2023-04-25 | https://www.group-ib.com/blog/meta-phishing-campaign/ | Inbound impersonation warning; not prevalence. |
| BC-S06 | Errors and Warnings; Google Ads Scripts team; updated 2026-06-24 | https://developers.google.com/google-ads/scripts/docs/troubleshooting/errors | Best-effort scripts; read-back required. |
| BC-S07 | Billing and payment suspensions; Google Ads Help; current/undated | https://support.google.com/google-ads/answer/13704200 | Billing/chargeback/verification states; account-specific. |
| BC-S08 | How to dispute a Google Ads charge; Google Ads Help; current/undated | https://support.google.com/google-ads/answer/10560092 | Reconciliation before dispute; no outcome promise. |
| BC-S09 | Manager Accounts (MCC): About Google Ads manager accounts; Google Ads Help; current/undated | https://support.google.com/google-ads/answer/6139186 | Access/link mechanics; not legal ownership proof. |
| PR-P01 | Status and outages of Meta business products; Meta; live/undated | https://metastatus.com/ | Product-scoped status, not exhaustive history. |
| PR-P07 | Meta Takes Legal Action Against Scam Advertisers; Meta Newsroom; 2026-02-26 | https://about.fb.com/news/2026/02/meta-takes-legal-action-against-scam-advertisers/ | Anti-scam/no-evasion posture. |
| PR-P09 | *History | Google Ads Status Dashboard*; Google; live/undated | https://ads.google.com/status/publisher/summary |
| PR-P10 | Google Ads account suspensions overview; Google Ads Help; current/undated | https://support.google.com/adspolicy/answer/9841640?hl=en | Suspension context; no universal outcome. |
| PR-P11 | Billing and payment suspensions; Google Ads Help; current/undated | https://support.google.com/adspolicy/answer/13704200?hl=en | Billing/verification context; labels vary. |
| PR-P12 | Secure your Google Ads account: Introduction; Google Ads Help; current/undated | https://support.google.com/google-ads/answer/2375456 | Access/security principles; no clean-account guarantee. |
| PR-P13 | About suspended ad accounts on TikTok; TikTok for Business; updated June 2026 | https://ads.tiktok.com/help/article/account-suspensions?redirected=1 | Account Health/suspension vocabulary; mutable. |
| PR-P15 | About transaction-related appeals; TikTok for Business; updated July 2026 | https://ads.tiktok.com/help/article/about-transaction-related-appeals | Transaction-risk context; case-by-case eligibility. |
| PR-P18 | Google Ads Experiencing Outage Impacting Key Features [Updated]; Matt G. Southern; Search Engine Journal; 2024-08-01, updated 2024-09-19 | https://www.searchenginejournal.com/google-ads-experiencing-outage-impacting-key-features/523624/ | Reported reporting/data-isolation incident; no prevalence. |
| PR-P24 | Malvertising campaigns take aim at Meta business accounts; SC Staff, SC Media; 2025-09-12 | https://www.scworld.com/brief/malvertising-campaigns-take-aim-at-meta-business-accounts | Reported extension/session threat; not an individual compromise conclusion. |
| PR-P21 | Google Ads stop running for some advertisers; Schwartz, Search Engine Land; 2025-03-02/03 | https://searchengineland.com/google-ads-stop-running-for-some-advertisers-452864 | Reported delivery symptom; cause/scope unclear. |
Related resources
- Facebook Ad Account Restricted — Recovery GuideYour Facebook ad account has been restricted — limited functionality, no new campaigns, or reduced spend limits. Here's why it happened and how to restore full access.
- How To Appeal a Meta Ad Account BanStep-by-step guide to writing a successful Meta ad account appeal. Includes templates, timing, escalation strategies, and what to do if your appeal is denied.
- Meta Ad Account Disabled — Recovery GuideYour Meta ad account has been disabled. Here's exactly what happened, how to appeal, and how to get back to running ads as fast as possible.
- Meta Business Manager Restricted? Request a ReviewMeta Business Manager restricted from advertising? Check the affected asset and reason in Business Support Home, then follow Meta's available review steps.
- How To Appeal a Google Ads SuspensionHow to write and submit a successful Google Ads suspension appeal. Templates, escalation strategies, and what to do if your appeal is denied.
- Google Ads Account Suspended — Recovery GuideYour Google Ads account has been suspended. Here's why, how to appeal, and what to do to get back to running campaigns on Google Ads.
- Google Ads Suspension Recovery — The Full RoadmapA step-by-step roadmap for recovering from a Google Ads suspension: how to triage the suspension type, which appeal channel to use, realistic timelines, and what to do if the appeal fails.
- Google Ads Account Suspended for Billing — Fix GuideYour Google Ads account has been suspended due to a billing issue — failed payment, suspected fraud, or expired card. Here's how to identify the exact issue and get your account back.
- How To Appeal a TikTok Ad Account SuspensionStep-by-step guide to appealing a TikTok Ads Manager suspension. Includes appeal templates, escalation paths, and whitelist strategies.
- TikTok Ad Account Suspended — Recovery GuideYour TikTok ad account has been suspended. Here's why it happened, how to recover, and how to prevent future suspensions on TikTok Ads Manager.
- TikTok Business Account Banned — Recovery GuideYour TikTok Business Center or Ads Manager account has been fully banned. Here's what caused it, what's recoverable, how to appeal, and when to escalate to TikTok business support.
- Ad Incident Evidence Capture Guide: Preserve the Record Before You Change the SystemPreserve ad evidence before changing access, billing, campaigns, tracking, domains, catalogs, integrations, or appeals.
- Ad Account Recovery Acceptance Checklist: Prove Operations Before Resuming SpendProve access, ownership, billing, dependencies, measurement, test delivery, monitoring, reconciliation, and closure before resuming ad spend.
- Platform Outage vs Account-Specific Problem: A Cross-Platform Incident ClassifierSeparate provider outages from account, reporting, local, and shared-dependency failures using path-distinct evidence and reversible controls.
- Ad Account Billing Interruption Reconciliation: Balance, Authorization, and RevenueReconcile ad balances, payment rails, agencies, credits, disputes, attribution, and revenue without premature chargebacks.
Contact AdsInfra
Send a message about this resource before making a high-impact change.